Assuring the Silver Review Reforms – The Critical Role of Risk Management and Assurance 10 min read This is blog 4 of a 4-part series.By Lauren Brown, Elly Maddy, and Daniel AgostaThe Silver Review sets out an ambitious reform agenda for the Victorian Public Service (VPS) – reshaping workforce structures, consolidating entities, tightening fiscal settings, and accelerating digital and AI adoption. For Chief Risk and Audit Officers and Executives, Secretaries, Deputy Secretaries, and Audit and Risk Management committees, the challenge is to provide confidence that this reform is being delivered in a way that protects public value, not just the bottom line. Topics Internal Audit and Corporate Governance Risk Management and Regulatory Compliance Technology Enablement Industries Government Reform at scale: why assurance matters more than everThe reforms flowing from the Silver Review are extensive and interconnected, spanning workforce reductions, entity consolidation and cessations, new budget rules, and major digital and AI initiatives. These changes are also occurring in a context of heightened public scrutiny, union concern, and constrained fiscal capacity.In this environment, risk management and assurance cannot be treated as compliance afterthoughts. They must act as strategic enablers, helping leaders understand where reform risks are highest, where controls are weakest, and where implementation is drifting from intent, so that timely course corrections can be made.Internal audit as strategic risk partnerInternal audit functions have a unique, whole-of-organisation vantage point across programs, entities, functions and enabling services. This perspective is critical when reforms cut across traditional boundaries, such as simultaneous workforce reductions, new operating models, and system changes.To support Silver Review implementation, internal audit plans should shift from a primarily cyclical, control based focus to more anticipatory coverage. This includes proactive advisory work on implementation governance, early stage reviews of reform design and change management processes, and targeted audits of high risk consolidation or savings initiatives before issues crystallise into service failures or integrity concerns. The following sections explore these and other considerations for assurance functions.Risk management in restructuring and entity reformRestructuring and entity reform create risks that extend well beyond organisational charts. Service continuity can be threatened if functions move faster than capabilities, control environments can be weakened when roles and processes shift, employee morale and retention of corporate knowledge can suffer if risks to employee wellbeing are not considered, and governance clarity can suffer where responsibilities are split across new structures.Risk leaders and assurance functions should ensure that entity changes and workforce rebalancing are supported by structured risk assessments that consider service impact, control redesign, stakeholder confidence, employee wellbeing, and regulatory obligations. This includes clarifying owners for key risks during transition, updating risk registers to reflect new structures, and ensuring that critical controls are re established quickly in new entities or operating models.Digital and AI assurance in practiceThe Silver Review’s emphasis on shared platforms, digitisation and AI creates a new layer of risk and assurance considerations. In response, core themes for risk and internal audit functions include a greater focus on data governance and quality, cyber security, algorithmic decision-making (i.e. the use of automated approvals or AI chatbots), and third-party and vendor risk for cloud and software-as-a-service solutions.For AI in particular, assurance activities should test whether digital and AI initiatives are being designed and operated with clear governance, defined accountability for decisions, and controls that address fairness, privacy, transparency and security. This includes assessing model risk management for AI, verifying the traceability and explainability of AI enabled decisions, and ensuring that digital transformations do not inadvertently undermine existing controls.Performance and benefits realisation auditBeyond financial savings, the Silver Review is intended to improve efficiency, service quality and long-term sustainability. Internal audit and risk functions are well placed to test whether these broader benefits are being realised, and to highlight where reforms are creating unintended consequences.This may involve auditing benefits realisation frameworks, checking the integrity of data used to report progress, and validating that key performance indicators reflect both efficiency and service outcomes. Independent review can help VPS leaders understand whether apparent savings are genuine, or whether they are being offset by lower quality, higher risk or cost transfer to other parts of the system.Governance, ethics and culture in the VPSReform on this scale will inevitably stress existing governance and cultural norms. There is a risk that pressure to deliver savings and meet milestones can crowd out frank and fearless advice, discourage escalation of issues, or create tolerance for shortcuts in process or oversight.Risk and assurance leaders should explicitly consider governance, ethics and culture within their work programs, testing whether decision making structures are functioning as intended, whether integrity and behaviour expectations are understood, and whether staff feel safe to raise concerns during change. This lens is particularly important in areas already under heightened community and parliamentary scrutiny.Assuring change management across the VPSThe success of the Silver Review will depend as much on how change is managed as on the technical quality of reform design. Poorly planned or communicated change can damage morale, increase attrition, and undermine the very capabilities needed to deliver reform.Internal audit and risk leaders can provide valuable insight by assessing the effectiveness of change management across major initiatives. This includes reviewing governance of change programs, stakeholder engagement and communication plans, training and capability uplift, and mechanisms for monitoring cultural and workforce impacts. Assurance over change management helps VPS leaders understand whether reforms are being implemented in a way that is sustainable for people as well as for budgets.Building a reformready internal audit and risk functionTo respond effectively, internal audit and risk functions will need to re-prioritise their plans and uplift skills in areas such as digital and data, AI, complex program delivery, and change risk.Integrated assurance planning, spanning internal audit, enterprise risk, finance, ICT, HR and safety, can help reduce duplication and close coverage gaps. By coordinating who looks at what, and when, leaders and Audit and Risk Committees gain a more coherent view of reform risks and control effectiveness.How Protiviti Australia can helpProtiviti understands that each VPS department and public sector entity is experiencing the Silver Review differently, with unique risk profiles, reform portfolios and assurance needs. A generic approach to assurance will not provide the confidence that leaders, committees and the community require.Our public sector specialists work with risk and internal audit leaders to design and deliver transformation focused assurance that is tailored to each organisation’s context, including:Portfolio level risk mapping and implementation governance reviews for major reform programs.Independent assurance over restructures, entity changes, shared services migrations, and new and redesigned process flows.Reviews of digital, data and AI risk management frameworks and related control environments.Assessment of change management effectiveness, including governance, communication and people related risks.Support for integrated assurance planning across internal audit, risk, finance and ICT functions.Our team has extensive experience supporting state and federal agencies through high profile reform and transformation, helping leaders demonstrate that change is being delivered safely, ethically and in line with public value expectations.Closing the series: where to from here?This final blog in Protiviti Australia’s four-part series has focused on the critical role of risk management and assurance in safeguarding the Silver Review reforms. Together, the series has explored what the Review means for VPS leaders, finance decision-makers, technology leaders and now assurance and risk functions, highlighting that sustainable reform requires disciplined governance, strong controls, responsible use of digital and AI, and careful stewardship of people and culture.Revisit the rest of the series:Blog 1: Resetting the Victorian Public Service: What the Silver Review Means for VPS LeadersBlog 2: Digitising the VPS – Shared Platforms, AI and the Responsibilities of Technology LeadersBlog 3: Silver Review Implications for VPS Financial Decision Makers: Guardrails, Savings and Financial Stewardship Find out more about our solutions: State Government At Protiviti, our state government consultants understand the unique operating models, regulatory frameworks and community expectations that shape state-level decision making. Our state government consulting solutions help governments modernise core services, manage complex portfolios, and deliver with confidence. Internal Audit We deliver world-class internal audit consulting, leveraging leading practises that we have helped define and shape for the profession. Innovation inspires and encourages. Technology and data enable and deliver insight and efficiency. Proven and contemporary methods drive results. Technology Our tech consulting services range from strategy, design and development through implementation, risk management and managed services. Every business is becoming a technology business. Let us help you transform. Finance Transformation Protiviti's finance transformation strategies help finance leaders address their current challenges, prepare for future challenges, and explore opportunities for continuous growth, delivering innovative solutions and supporting the finance function as a forward-thinking, strategic partner for the business. Featured blogs BLOGS Protiviti's Perspectives on the Silver Review 5 min read This four-part blog series presents Protiviti’s perspectives on how the Victorian Public Service can turn the Silver Review from a cost‑cutting exercise into a system‑level reform opportunity that strengthens financial sustainability, digital... BLOGS Resetting the Victorian Public Service: What the Silver Review Means for VPS Leaders 9 min read Recent ransomware attacks and new SEC cyber disclosure rules have increased the focus on cyber resilience across nearly all industries. As a result, many companies have invested substantial resources to help manage and mitigate cybersecurity risk to... BLOGS Digitising the VPS: Shared Platforms, AI and the Responsibilities of Technology Leaders 10 min read Victorian Public Service (VPS) Chief Information Officers (CIOs) and Chief Technology Officers (CTOs) face a defining moment with the Silver Review. The Review positions digital transformation and AI as central to delivering sustainable savings and... BLOGS Silver Review Implications for VPS Financial Decision Makers: Guardrails, Savings and Financial Stewardship 10 min read Victorian Public Service (VPS) leaders are at the centre of the Silver Review’s implementation challenge. As the Review moves from recommendations to action, senior financial decisionmakers in departments and agencies – including CFOs – will be key... Previous Article Pagination Next Article About the authors Elly Maddy Elly is a director at Protiviti Australia and provides internal audit services to federal and state government departments and agencies. Elly is known for her innovative problem-solving approach and for providing her clients with new approaches to their operational issues. Over 13 years, she has accumulated valuable experience that provides a sound understanding of the complexities, challenges and unique funding and regulatory environment in which her clients operate.She currently leads the delivery of outsourced and co-sourced internal audit and assurance services to several government departments and agencies across Victoria and the ACT, working directly with senior leadership and chief audit executives to deliver high-quality, risk based internal audit programs. Daniel Agosta Daniel is an associate director at Protiviti Australia and delivers internal audit, risk management, and compliance services to public sector, corporate, healthcare, and medical research clients. Known for his client-centric solutions and analytical approach, Daniel combines practical knowledge with a commitment to continuous improvement to help organisations navigate complex operational and regulatory challenges.With seven years as an internal audit professional and recently qualified CPA, he has developed deep expertise in internal audit, operational performance improvement, and compliance audits. Daniel currently leads the delivery of tailored internal audit and advisory projects for public sector departments and agencies, working closely with public sector leaders, CFOs, and chief audit executives to provide assurance over risk management and controls. Lauren Brown Lauren is the country lead for Protiviti Australia with more than two decades of experience working with a range of clients including the public sector, multinationals and private sector organisations in Australia and abroad. She specialises in governance, risk, and internal controls, across multiple industries including health, higher education, federal and state government, consumer products, and energy.Lauren has extensive experience working with various stakeholder groups including boards, audit committees, executive management teams and line management staff and has acted as an active member and contributor to the Institute of Internal Auditors since 2014. Rita Gatt As managing director, technology and cybersecurity at Protiviti, Rita leads a dedicated team focused on solving complex organisational challenges, with a particular emphasis on leveraging data, AI and technology to do so. With over 20 years of experience navigating complex regulatory landscapes, strengthening security frameworks, and managing technology and data-driven risk, she has a proven track record of modernising businesses and enhancing performance at scale for some of the world’s most recognised brands.She is passionate about the future of technology and has contributed to national discussions on cyber resilience and quantum preparedness. Her enthusiasm lies in developing forward-thinking strategies that drive growth and productivity for Australia’s largest corporations. She thrives on translating visionary concepts into practical, results-oriented solutions, leveraging top-tier talent and strategic partnerships. Leadership Elly Maddy Elly is a director at Protiviti Australia and provides internal audit services to Federal and State government departments and agencies. Elly is known for her innovative problem-solving approach and for providing her clients with new approaches to their operational ... Learn More Daniel Agosta Daniel is an associate director at Protiviti Australia and delivers internal audit, risk management, and compliance services to public sector, corporate, healthcare, and medical research clients. Known for his client-centric solutions and analytical approach, Daniel ... Learn More Lauren Brown Lauren is the country lead for Protiviti Australia. With over 14 years' experience in governance, risk, and internal control, she specialises across multiple industries including health, higher education, government, consumer products, and energy. She is an active ... Learn More Rita Gatt As managing director, technology and cybersecurity at Protiviti, Rita leads a dedicated team focused on solving complex organisational challenges, with a particular emphasis on leveraging data, AI and technology to do so. With over 20 years of experience navigating ... Learn More